ARCHIVED
This job listing has been archived and is no longer accepting applications.
MisuJob - AI Job Search Platform MisuJob

SIEM Engineer

Sofiastars

Sofia City, Bulgaria (Belgrade, Serbia, Lisbon, Portugal, Sofia, Bulgaria, Valencia, Spain, Warsaw, Poland, Yerevan, Armenia) Remote permanent

Posted: February 7, 2026

Interested in this position?

Create a free account to apply with AI-powered matching

Quick Summary

We are seeking a skilled SIEM Engineer to join our team in Sofia, Bulgaria, to design and implement security solutions for online businesses.

Job Description

Sofia Stars is an operational services company based in Sofia. We offer a range of solutions for online businesses, including R&D, Marketing, Customer Support, KYC, Risk, and Anti-Fraud services. With 300+ bright stars on our team, we deliver secure, reliable solutions with a touch of quality that shines. When you join us, you’ll be part of a place where ideas light up, and growth isn’t just a promise—it’s a journey.

‼️ Important: This is an on-site position at one of our offices in:

• Belgrade (Serbia),

• Lisbon (Portugal),

• Sofia (Bulgaria),

• Valencia (Spain),

• Warsaw (Poland),

• Yerevan (Armenia).

Remote or hybrid work is not available. Candidates must either already be in the location or be willing to relocate. The relocation support will be provided if necessary.

We are seeking an SIEM Engineer to join our team at one of our offices.

✅ Responsibilities:
✔️ Design, implement, and maintain the organization’s SIEM platform to ensure continuous, reliable, and scalable security monitoring.
✔️ Develop and manage log source integrations across on-premise, cloud, and hybrid environments (e.g., infrastructure, applications, identity providers, endpoints).
✔️ Build, fine-tune, and maintain correlation rules, detection logic, and alerting workflows to identify potential threats and anomalous behavior.
✔️ Create and maintain dashboards, reports, and visualizations to support SOC operations, threat hunting, and management visibility.
✔️ Continuously optimize SIEM performance and data ingestion efficiency, including parsing, filtering, and normalization of logs.
✔️ Collaborate with Security Operations, Incident Response, and Threat Intelligence teams to improve detection coverage and response playbooks.
✔️ Conduct periodic use case reviews to ensure alignment with evolving threat landscape and business priorities.
✔️ Ensure proper data retention, storage, and access control configurations within the SIEM in accordance with internal policies and compliance standards.
✔️ Automate repetitive processes and data enrichment using scripting or integrations with SOAR and external APIs.
✔️ Document correlation rules, workflows, and integration procedures to maintain knowledge continuity.
✔️ Support audits and compliance reporting by ensuring log completeness, traceability, and integrity.
✔️ Participate in on-call or escalation rotations for critical security incidents where SIEM expertise is required.
✔️ Evaluate and recommend improvements to SIEM architecture, detection capabilities, and related toolsets.
✔️ Contribute to the roadmap and maturity development of the organization’s security monitoring and detection engineering functions.

✅ Requirements:
✔️ 3+ years of experience working with SIEM platforms (e.g., Splunk, ELK, QRadar, or similar).
✔️ 9+ months of experience working with ELK SIEM (Elasticsearch, Logstash, Kibana, and Beats).
✔️ Strong understanding of log management, event correlation, and alerting principles.
✔️ Hands-on experience with log ingestion, parsing, and normalization from multiple sources.
✔️ Proficiency in developing and tuning detection rules, dashboards, and reports.
✔️ Good knowledge of security operations, incident response, and threat detection processes.
✔️ Familiarity with common network, endpoint, and cloud security data sources.
✔️ Experience with scripting (Python, PowerShell, or similar) for automation and data enrichment.
✔️ Understanding of MITRE ATT&CK framework and its application in detection engineering.
✔️ Strong analytical and troubleshooting skills.
✔️ Effective communication and documentation skills.
✔️ Fluency in English (written and spoken).

✅ Nice to have:
✔️ Experience with SOAR platforms.
✔️ Experience with EDR.
✔️ Experience with cloud environments (AWS, Azure, GCP) and related log sources.
✔️ Familiarity with vulnerability management and exposure reduction processes.
✔️ Knowledge of regulatory and compliance requirements (GDPR, ISO 27001, SOC 2, etc.).
✔️ Previous experience working in a global or distributed Security Operations environment.

✅ We offer excellent benefits, including but not limited to:
🏖️ Up to 25 vacation days;
🤒 6 Undocumented Sick Leave Days;
💷 Monthly food vouchers (102 EUR);
🏥 Private Medical Insurance;
🏋🏼 Multisport Card;
🎁 Birthday, Wedding and Newborn gifts;
🍔 Breakfast, Friday lunches, fruits, and snacks in the office;
🎭 Monthly company activities and team-building events;
🚀 Career growth opportunities.

Ready to shine? Let’s make it real.

By submitting your application, you agree to our Privacy Policy.

Why Apply Through MisuJob?

AI-Powered Job Matching: MisuJob uses advanced artificial intelligence to analyze your skills, experience, and career goals. Our matching algorithm compares your profile against thousands of job requirements to find positions where you have the highest chance of success. This saves you hours of manual job searching and ensures you only see relevant opportunities.

One-Click Applications: Once you create your profile, applying to jobs is effortless. Your resume and cover letter are automatically tailored to highlight the most relevant experience for each position. You can apply to multiple jobs in minutes, not hours.

Career Intelligence: Beyond job matching, MisuJob provides valuable career insights. See how your skills compare to market demands, identify skill gaps to address, and understand salary benchmarks for your experience level. Make data-driven decisions about your career path.

Frequently Asked Questions

How do I apply for this position?

Click the "Register to Apply" button above to create a free MisuJob account. Once registered, you can apply with one click and track your application status in your dashboard.

Is MisuJob free for job seekers?

Yes, MisuJob is completely free for job seekers. Create your profile, get matched with jobs, and apply without any cost. We help you find your dream job without any hidden fees.

How does AI matching work?

Our AI analyzes your resume, skills, and experience to understand your professional profile. It then compares this against job requirements using natural language processing to calculate a match percentage. Higher matches mean better fit for the role.

Can I apply to jobs in other countries?

Absolutely. MisuJob features jobs from companies worldwide, including remote positions. Filter by location or look for remote opportunities to find jobs that match your preferences.

Ready to Apply?

Join thousands of job seekers using MisuJob's AI to find and apply to their dream jobs automatically.

Register to Apply